Trust

How Hygieia handles patient information

You're trusting Hygieia inside the exam room, so here is exactly what happens to what you record, type, and store — in plain language, including the parts most products leave out.

The short version

  • Notes are stored tokenized: patient identities live in a separate, access-controlled vault and are joined back only on your screen.
  • Our AI language model never sees a patient identity — it works entirely on placeholder tokens like [PT_NAME] and [DATE_1].
  • Encounter audio goes to one place only: a HIPAA business-associate medical transcription service, transiently, to produce your transcript.
  • Everything is encrypted in transit and at rest. We sign a Business Associate Agreement with your practice, and every vendor that touches protected health information has signed one with us.

Where your data lives

Notes, transcripts, and your preferences are stored in Google Cloud (United States) under a Business Associate Agreement, encrypted at rest and in transit. Patient identities are not stored inside notes — they live in a separate identity vault, and every read and write of that vault is gated and audited. On your phone, the clinical database is fully encrypted, its keys are protected by your device's biometric hardware, and the app locks itself when you step away.

What AI services can and cannot see

ServiceWhat it receivesAgreement
Anthropic — drafts your noteTokenized text only: placeholders, never names, dates of birth, or record numbersBusiness Associate Agreement
Deepgram — medical transcriptionEncounter audio, transiently, to return your transcript; nothing is retained on their sideBusiness Associate Agreement
Google Cloud — storage & computeThe encrypted data described aboveBusiness Associate Agreement

An honest note about audio: a recording naturally contains whatever was said aloud — names included. That is why transcription happens only under a business-associate agreement, why audio is never sent to the language model, and why de-identification runs on the transcript before any text moves on to AI drafting.

What never carries patient information

Emails from Hygieia never contain patient information. Push notifications are content-free — the app fetches what it needs over an authenticated connection. Application logs record identifiers and counts, never clinical content.

Retention and deletion

Encounter audio is kept only until it has done its job: once a transcript and note exist, it is deleted automatically after a short retention window, and you can delete it sooner yourself. Audio that has not yet been transcribed is deliberately kept longer — it may be your only record of the visit. Deleting your account deletes your data; the limited billing and audit ledgers we are required to keep contain no clinical content.

Inside your practice

Access is per-physician by default. Staff you invite see only notes you have signed off, under role-based access, and their identity reads are audited. Signing in to the web dashboard requires two-step verification; the mobile app is protected by your device biometric.

If something ever goes wrong

We maintain a written security risk analysis reviewed annually, daily backups with point-in-time recovery, and a breach-response playbook. If an incident affects your patients' information, we will notify your practice without unreasonable delay, within the timelines committed in our Business Associate Agreement — with facts, not spin.

A few honest limits

No system is breach-proof, and we won't pretend otherwise. Our commitments are structural: minimize what any party — including our own AI services — can ever see, encrypt everything, audit access to identities, and tell you the truth quickly if something goes wrong.

One practical tip

On shared or hospital workstations, sign out when you step away.

Questions about any of this? Visit our support page. See our Privacy Policy and Terms of Service for more.